Sceawere
Vulnerability Detail
CVE-2026-105647UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Server-Side Request Forgery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4
- Creation Date
- 2h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.0",
"pubDate": "2026-10-05T20:17:13.157Z",
"pubdate": "2026-10-05T20:17:13.157Z",
"executiveSummary": "A server-side request forgery (SSRF) vulnerability exists in the Ghost content management system, specifically impacting the Webmentions functionality. This flaw allows unauthenticated, remote attackers to coerce the Ghost application server into initiating arbitrary HTTP requests toward internal network resources.\nThe vulnerability resides in improper input validation within the system's request handling logic. By manipulating the parameters associated with Webmentions, an attacker can bypass security boundaries to interact with internal services that are otherwise inaccessible from the public internet.\nAlthough the current exploitation vector does not return response data to the attacker, the vulnerability facilitates reconnaissance, port scanning, and the potential exploitation of internal services or non-public APIs.\nThis issue affects Ghost versions 6.54.1 through 6.65.0. Organizations running these versions are exposed to internal network probing. Successful exploitation requires no prior authentication or administrative privileges, significantly lowering the barrier for entry. The vulnerability is remediated in version 6.65.0.",
"technicalDetails": "The vulnerability is a server-side request forgery (SSRF) originating from insufficient validation of user-supplied URLs within the Webmentions component of Ghost. When processing a Webmention, the application fails to adequately sanitize or restrict the target hostname/IP address before performing a backend HTTP request.\nThe root cause is a lack of robust allow-list or block-list validation for outbound connection requests. Because the server-side logic trusts the user-provided destination URI without confirming it resolves to a public-facing entity, the underlying Node.js request libraries execute the fetch operation directly from the server's execution context.\nThe attack flow proceeds as follows: An unauthenticated attacker identifies the Webmentions endpoint and submits a crafted request containing an internal URI (e.g., http://127.0.0.1:[port] or a private IP address within the server's local subnet). The Ghost application, acting as a confused deputy, initiates an outbound HTTP request to the specified internal target. This allows the attacker to reach restricted services, such as database management interfaces, internal metadata services, or configuration endpoints that lack public authentication.\nWhile the vulnerability description specifies that no response data is returned to the attacker (blind SSRF), the impact remains severe. The attacker can infer the existence of internal services through timing attacks (observing latency differences between open and closed ports) or by observing service behaviors, such as error codes or successful connection attempts if the internal service triggers secondary actions.\nThis vulnerability is present in Ghost versions 6.54.1 to 6.65.0. Because the application logic does not distinguish between internal and external infrastructure, the server effectively acts as a proxy for the attacker. Mitigation requires enforcing strict URL validation, implementing network-level egress filtering to prevent the application from communicating with non-routed or private network address spaces (RFC 1918), and ensuring the underlying Node.js environment is configured to prevent requests to local loopback addresses.\nThe fix provided in version 6.65.0 likely introduces stricter validation logic to intercept and reject URIs that resolve to internal network identifiers, ensuring that the Webmentions feature only facilitates legitimate interactions with external web resources."
}